[squid-users] Squid4 with GnuTLS - specify ciphers or disable protocols

Martin Hoffmann m.hoffmann.bs at gmail.com
Mon Nov 12 10:05:46 UTC 2018


Thanks for your quick reply.

Are your sure that tls-options *is working*?

It seems that no matter what options I give to tls-options everything is
ignored:

https_port 192.168.x.y:443 tls-cert=/path/cert.crt tls-key=/path/cert.key
tls-dh=/path/dhparams.pem tls-options=NORMAL:-VERS-TLS1.0 accel defaultsite=
my.domain.com

I have even tried tls-options=SECURE128:+SECURE192:-VERS-ALL:+VERS-TLS1.2
- but in the end its all the same, TLS 1.0, 1.1 and 1.2 are enabled and all
the same cipher suites are active. Absolute identical to omitting
tls-options=... altogether.

Any idea?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20181112/4b5c7322/attachment.html>


More information about the squid-users mailing list